Skip to main content

Cloud Storage Risks for UK Journalists

Google Drive, iCloud, and Dropbox are convenient — but for journalists handling sensitive material, they carry legal and security risks that must be understood and managed.

General guidance, not professional security advice. For high-risk threat models involving state actors or organised crime targeting, consult a qualified security professional or the Access Now Digital Security Helpline.

Last reviewed: Next review due:

The core risk: data you upload is data that can be compelled

When you upload a file to a mainstream cloud storage provider, you are handing a copy of that file to a company that can be legally compelled to produce it. In the UK, a production order under PACE or an equipment interference warrant under the IPA 2016 can require a provider to produce your files. US providers can be served US orders under the CLOUD Act, which has a broader reach than UK law in some respects.

This does not mean you should never use cloud storage. For the vast majority of journalism, it poses no practical risk. The issue arises when cloud storage is used for: unpublished investigation notes; source contact details; raw interview recordings; or documents received from sensitive whistleblowers. For this material, the alternatives below significantly reduce your exposure.

Provider risk comparison

Google Drive / Google OneHigh for sensitive use

US company. CLOUD Act and US legal orders apply. Google can read your files. Large data requests transparency report published annually.

iCloud (Apple)High for sensitive use

US company. Apple Advanced Data Protection (ADP) provides E2E encryption if enabled — but only in some regions and for some data types. Verify your settings. Standard iCloud is not E2E encrypted.

DropboxHigh for sensitive use

US company. Dropbox encrypts data in transit and at rest, but holds the encryption keys. Can produce decrypted files under legal order.

Cryptomator + any cloudLower for sensitive use

Free, open-source client-side encryption. You encrypt before uploading. Provider only sees ciphertext. Works with any provider. You manage the key.

TresoritLower for sensitive use

Swiss/EU company. Zero-knowledge encryption. Provider cannot read your files. Designed for regulated industries and privacy-sensitive use. Commercial.

Proton DriveLower for sensitive use

Swiss company, same organisation as ProtonMail. End-to-end encrypted, open-source clients. No access to file contents by provider. Competitive pricing.

Red flags

  • Storing unpublished investigation notes or source contact details in Google Drive or iCloud.
  • Sharing a Dropbox link with a sensitive source.
  • Using a work Microsoft OneDrive account for personal investigation research — your employer can access it.
  • iCloud backups of your iPhone enabled without Apple Advanced Data Protection turned on.
  • Assuming that a password on a cloud folder makes it inaccessible to the provider.

Cloud storage security checklist

  • I do not store unpublished sensitive investigation material in mainstream cloud storage (Google Drive, Dropbox, OneDrive).
  • If I use iCloud, I have enabled Apple Advanced Data Protection in my iPhone Settings.
  • For sensitive documents, I use Cryptomator to encrypt before uploading to any cloud provider.
  • For high-sensitivity material, I use Proton Drive or Tresorit (zero-knowledge providers).
  • I do not use work-owned cloud storage for personal investigation research or source communications.
  • I have reviewed what my phone automatically syncs to iCloud or Google Photos (including documents, contacts, messages).

Source protection checklist

Cloud storage decisions are part of your source protection posture. Assess your full workflow.

Source Protection Checklist

Common mistakes

  • Assuming cloud storage is secure because it requires a password to log in.
  • Not reviewing automatic backup settings — iCloud and Google can sync far more than you realise.
  • Using a work cloud account for private investigation research — employers have access.
  • Downloading documents from a source into Google Drive without considering the metadata implications.
  • Confusing in-transit encryption (standard) with zero-knowledge encryption (rare) — most providers offer the former only.

Related guides

Primary sources

Frequently asked questions

Can UK police or courts access my Google Drive or iCloud?
Yes. UK law enforcement can serve a production order under the Police and Criminal Evidence Act 1984 (PACE) or an order under the Investigatory Powers Act 2016 on a cloud storage provider, requiring them to produce data they hold. US-based providers (Google, Apple, Microsoft, Dropbox) can also be compelled by US law enforcement under the CLOUD Act. Responses to these orders are often subject to non-disclosure obligations, so you may not be informed.
What is Cryptomator and how does it help?
Cryptomator is a free, open-source tool that encrypts files on your device before they are uploaded to cloud storage. Your cloud provider stores only encrypted data and cannot read the contents. The encryption key never leaves your device. This means even if your cloud provider receives a production order, it can only produce encrypted ciphertext — useless without your key. It works with any cloud storage provider (Google Drive, Dropbox, etc.).
What is a zero-knowledge cloud storage provider?
A zero-knowledge provider is designed so that the company never has access to your encryption keys. Your files are encrypted before they reach the provider's servers, and only you can decrypt them. Tresorit and Proton Drive are examples. In contrast, mainstream providers (Google, Apple, Microsoft) hold the keys to your files and can produce decrypted content if legally compelled.
Does UK GDPR protect journalist data in cloud storage?
UK GDPR gives individuals rights over their personal data — but it primarily governs how organisations process your data, not whether law enforcement can access it. Lawful access powers (PACE, IPA 2016) override GDPR protections. UK GDPR does require cloud providers to have appropriate security measures, but this does not prevent lawful interception.